Crypto news

07.08.2026
03:53

Coldcard Mk3 cold wallet: a public experiment showed how quickly hackers drain unprotected accounts

In the world of hardware crypto wallets, security is not just a feature but a matter of fund survival. Recently, I conducted my own research that clearly demonstrates how dangerous overconfidence can be for owners of cold storage. The focus was on the popular Coldcard Mk3 — a device that many consider the gold standard of protection. My experiment showed that even a slight underestimation of threats can lead to the instant loss of all digital assets.

I generated a secret phrase on the Coldcard Mk3 with firmware version 4.1.8 and created five different wallets, each of which received the same amount in satoshis. The goal was to test how quickly attackers react to the appearance of new, potentially vulnerable addresses on the network. It is important to emphasize that the issue affects not only the Mk3 but also newer models — the Mk4, Mk5, and even the Q.

Methodology and test parameters

For the sake of a clean experiment, all wallets used a single standard of bc1q addresses, the same key derivation path, and were funded with 10,800 satoshis each. The only difference was the protection configuration:

  • Wallet #1: standard, without an additional passphrase.
  • Wallet #2: with a password consisting of one word from the BIP39 list.
  • Wallet #3: with a password consisting of two BIP39 words.
  • Wallet #4: with a password consisting of three BIP39 words.
  • Wallet #5: with a random account number (from 1 to 9999).

During the setup process, a technical hiccup occurred: exporting public keys to the Sparrow wallet caused a failure, and the device stopped responding to commands. I had to resort to saving CSV files to an SD card — which, by the way, serves as a reminder that even top-tier devices have their quirks.

Results: the speed of the attack is shocking

The result exceeded all expectations. The basic wallet without a passphrase was drained almost instantly. As soon as I opened the mempool explorer, the funds had already been transferred to a new unknown address. This means that hackers had pre-loaded compromised keys into their automated bots, which scan the blockchain for such "easy" targets.

The remaining four wallets, including the one with the account number, remained untouched. However, this is no reason to celebrate: the secret phrase itself, generated by the device, is considered fully vulnerable. Monitoring of these addresses' activity continues in real time.

My analysis: This experiment is a vivid confirmation that a hardware wallet without a reliable passphrase (BIP39 passphrase) is just a pretty piece of hardware with a false sense of security. Attackers do not crack cryptography; they exploit human laziness and carelessness. Owners of Coldcard and other hardware devices should take this test as a stern warning: minimal additional protection is not a recommendation but a mandatory condition for storing any significant amounts. Otherwise, you are simply handing your coins over to automated bots that work faster than you can blink.